CVE-2026-93760 Overview
CVE-2026-93760 is a NoSQL injection vulnerability in Mongoid, the official Ruby Object-Document-Mapper (ODM) for MongoDB. Mongoid does not restrict which query operators may originate from caller-supplied filter data when an application passes that data to its query-building methods. Applications that forward externally supplied filter parameters directly into Mongoid queries expose the database to operator injection by unauthenticated attackers. Successful exploitation can disclose stored field values and degrade database performance. The issue is tracked under [CWE-943: Improper Neutralization of Special Elements in Data Query Logic].
Critical Impact
Unauthenticated remote attackers can inject MongoDB query operators through user-controlled filter parameters, causing unintended data disclosure and reduced database performance.
Affected Products
- MongoDB Mongoid (Ruby ODM library)
- Mongoid version 9.1.0
- Applications forwarding caller-supplied filter data into Mongoid query-building methods
Discovery Timeline
- 2026-09-18 - CVE-2026-93760 published to the National Vulnerability Database (NVD)
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-93760
Vulnerability Analysis
Mongoid translates Ruby hash arguments into MongoDB query documents. When an application passes user-supplied parameters directly into methods such as where, find_by, or dynamic finders, Mongoid does not filter out MongoDB query operators embedded in that input. Operators prefixed with $, including $ne, $gt, $regex, $where, and $exists, are forwarded to the database as legitimate query directives.
An attacker who controls a request parameter can substitute a scalar value with a nested structure that expresses a query operator. This transforms an equality lookup into a broader match condition, an inequality test, or a server-side JavaScript evaluation. The database processes the crafted query and returns rows the caller was never authorized to see.
The issue affects confidentiality of stored field values and can also affect availability. Operators such as $regex with unanchored patterns or $where with expensive JavaScript expressions force full collection scans and CPU-intensive evaluation.
Root Cause
The root cause is missing input sanitization at the ODM boundary. Mongoid trusts the shape of the hash it receives and does not distinguish between developer-authored operators and operators embedded in external input. The library provides no default allowlist of permissible operator keys for caller-supplied filter data.
Attack Vector
The attack vector is network-based and requires no authentication or user interaction. An attacker submits an HTTP parameter whose value is a nested object encoding a MongoDB operator, for example, sending filter[email][$ne]= against an endpoint that queries by email. When the framework parses this into a Ruby hash and Mongoid receives it, the operator is honored during query construction. See the MongoDB JIRA Issue MONGOID-5994 for vendor tracking.
Detection Methods for CVE-2026-93760
Indicators of Compromise
- HTTP request parameters containing MongoDB operator keys such as $ne, $gt, $regex, $where, $exists, or $in in nested query string or JSON payloads.
- Unexpected spikes in MongoDB query duration and CPU utilization tied to specific collections queried by Mongoid.
- Application logs showing query filters with nested hash structures on parameters that should accept scalar values.
Detection Strategies
- Instrument Mongoid query construction to log any filter hash containing keys that begin with $ and originate from request parameters.
- Enable MongoDB profiler at level 1 or 2 to capture slow or unusual queries, and correlate them with application request identifiers.
- Review web application firewall (WAF) telemetry for request bodies and query strings containing $-prefixed keys inside nested parameters.
Monitoring Recommendations
- Baseline normal query shapes per collection and alert on operators that deviate from that baseline.
- Monitor serverStatus metrics for elevated opcounters.query and globalLock contention on collections accessed by Mongoid applications.
- Forward MongoDB audit and slow-query logs to a centralized analytics platform for correlation with application-layer telemetry.
How to Mitigate CVE-2026-93760
Immediate Actions Required
- Audit all controllers and service objects that pass request parameters into Mongoid query methods such as where, find_by, and dynamic finders.
- Coerce user-supplied filter values to expected scalar types before they reach Mongoid, rejecting hashes and arrays where not expected.
- Apply strong parameter allowlisting in Rails controllers and reject keys beginning with $ from nested parameter structures.
- Deploy WAF rules that block request parameters containing MongoDB operator syntax.
Patch Information
Refer to the vendor tracking record at MongoDB JIRA Issue MONGOID-5994 for the current remediation status and fixed release information. Upgrade Mongoid to the vendor-supplied fixed version once available and retest affected query paths.
Workarounds
- Wrap query construction in a helper that recursively strips keys beginning with $ from any caller-supplied hash before passing it to Mongoid.
- Use explicit query builders that accept only scalar equality parameters instead of forwarding whole parameter hashes.
- Enforce strict schema validation on inbound API payloads using a library such as dry-validation to reject unexpected nested structures.
- Disable server-side JavaScript execution in MongoDB by setting security.javascriptEnabled: false to blunt the impact of $where injection.
# Configuration example: Rails strong parameters with type coercion
# app/controllers/users_controller.rb
def user_filter
raw = params.require(:filter).permit(:email, :status)
{
email: raw[:email].to_s,
status: raw[:status].to_s
}.reject { |_, v| v.empty? }
end
# Usage forces scalar values, blocking operator injection
User.where(user_filter)
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
